feat(instrumentation): close R44 gap — throw-site capture for use cases + controllers

Plan 10 documented R44 (capture at originating-throw layer) but only the
R43 repo leg was wired. captureException had zero call sites in any
controller or use-case body. This commit closes the gap.

Mechanism:
- Extract __sentryReported flag helpers into core-shared/instrumentation/
  reported-flag.ts. SentryLogger switches to importing them; RecordingLogger
  carries an inlined copy (tooling → core boundary disallows the import).
- Add withCapture(logger, tags, fn) higher-order wrapper paralleling
  withSpan. On throw: capture-with-tags, mark, re-throw. Bail if the flag
  was already set — covers the bubbled-from-repo case so each error
  surfaces in the logger exactly once with the inner-most layer's tags.
- Apply withSpan(withCapture(factory)) in every feature's bind-production
  and bind-dev-seed: auth (3 use cases × 3 controllers), blog (3×3),
  marketing-pages (2×2), navigation (1×1), media (3×3). Span is outermost
  so the errored span timing reflects the capture-and-rethrow.
- RecordingLogger.captureException now also honours the flag — test
  capture counts stay honest when both repo and outer layer wrap.

Tests:
- packages/core-shared/src/instrumentation/with-capture.test.ts —
  4 cases covering success, capture-on-throw, mark-on-capture, no-double
  via the flag.
- packages/blog/tests/r44-no-double-capture.test.ts — 3 cases: repo throw
  → 1 capture with repo tags; controller parse fail → 1 capture with
  controller tags; success → 0 captures.

Verification: pnpm test 26/26, pnpm lint 15/15, pnpm typecheck 14/14.

Docs: ADR-014 and the refactor log gain a "Post-merge follow-up" section
recording the gap, the fix, and the underlying lesson (don't describe
intent as shipped state — grep first).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-05-08 00:28:22 +02:00
parent 1771be3034
commit f0775d6ecc
19 changed files with 580 additions and 74 deletions

View File

@@ -0,0 +1,40 @@
import type { ILogger } from "./logger.interface";
import { isReported, markReported } from "./reported-flag";
/**
* Higher-order wrapper applied at DI bind time. Mirrors `withSpan`: takes a
* factory result `(args) => Promise<R>` and returns the same shape, but any
* thrown error is captured via `logger.captureException(err, { tags })` before
* being re-thrown.
*
* Skips capture if the error already carries the `__sentryReported` flag —
* this is what prevents double-capture when the same error bubbles through
* a wrapped repo → use case → controller chain (the repo's catch site
* captures first; outer wrappers see the flag and bail).
*
* Usage at bind time:
*
* const captured = withCapture(logger, { feature: "blog", layer: "use-case", name: "blog.getArticles" }, factory(deps));
* const wrapped = withSpan(tracer, opts, captured);
*
* Span wraps capture: the span timing reflects the captured-and-rethrown
* failure (errored span gets a duration), and the capture has accurate
* tags by the time it fires.
*/
export function withCapture<Args extends unknown[], R>(
logger: ILogger,
tags: Record<string, string>,
fn: (...args: Args) => Promise<R>,
): (...args: Args) => Promise<R> {
return async (...args) => {
try {
return await fn(...args);
} catch (err) {
if (!isReported(err)) {
logger.captureException(err, { tags });
markReported(err);
}
throw err;
}
};
}